Microsoft 365 Safe Attachments — does it block malicious email attachments?
Microsoft 365 Safe Attachments is the attachment-scanning feature in Microsoft Defender for Office 365 that opens suspicious files in an isolated sandbox and blocks malicious payloads before they reach Exchange Online inboxes; correctly applied policies will quarantine threats automatically for end users.
Configure Safe Attachments correctly and test it
Many UK businesses enable Safe Attachments but leave default rules that only partially protect mail flow. Start by selecting the correct policy mode: Block for high-risk inbound mail and Dynamic Delivery where you need the recipient to access benign content quickly while detonation completes. In the Microsoft 365 Security portal you can scope policies by recipient group, connector or domain which matters when partners or legacy systems are involved.
Practical steps to configure and validate:
- Review which mailboxes and connectors import external mail; apply Safe Attachments to Exchange Online and any hybrid connectors.
- Choose policy mode: use Block for external, unknown senders; use Monitor temporarily when first testing to reduce disruption.
- Enable notification for quarantine owners so your IT lead sees blocked files and can release false positives.
- Run end-to-end tests: send sample benign-but-suspicious files from a personal account, confirm they are sandboxed and that recipients get an appropriate message.
Keep a short test plan (five to eight scenarios): large ZIPs, macro-enabled Office files, password-protected archives, and email with both attachment and URL. Document the expected action for each scenario and who can override quarantines. If you need hands-on help configuring policies or interpreting detections, arrange Microsoft 365 support via your IT partner or use a specialist; for example, our Microsoft 365 support service can help with policy mapping and validation: Microsoft 365 support.
Operationalise monitoring, reporting and compensation controls
Safe Attachments reduces risk from malicious files, but it is not a complete defence on its own. You must pair it with monitoring, user controls and recovery plans so incidents are remediated quickly and business impact is limited. Set up an operator workflow that turns detections into actions — triage, escalate, restore — with named owners and SLAs.
Concrete items to put in place:
- Alerting and playbooks. Configure SIEM or Microsoft Sentinel to ingest Defender alerts and create a simple playbook: within 15–60 minutes an analyst reviews high-confidence blocks and confirms whether the file was business-critical.
- Quarantine review cadence. Assign a weekly triage slot for low/medium detections and an immediate response channel for high-risk items. Keep release logs so you can audit who allowed a file through.
- User-facing controls. Train staff on how quarantines appear in Outlook and the corporate mobile apps so they don’t bypass security by using personal email for file exchange.
- Compensating controls. Where Safe Attachments cannot inspect (for example, encrypted attachments), require secure file transfer alternatives or Content Disarm and Reconstruction (CDR) processes for high-value workflows.
Also validate recovery and forensics: ensure mailbox forensics retains copies of blocked messages for at least 90 days (or your regulatory retention period) and that your incident log links the Defender alert ID to the ticket. For guidance on wider email security practices, consider NCSC’s advice on secure email handling: NCSC’s guidance on email security. These operational controls turn detections into measurable reductions in downtime and risk.
Related reading
- our microsoft 365 support for business guide
- Microsoft 365 security audit service: what UK SMEs need to know
- Microsoft 365 Safe Links setup — enable Safe Links in Defender for Office 365
- Cost of Microsoft 365 managed services — a practical guide for UK businesses
- How to set up Microsoft 365 tenant: a sensible path for UK SMEs
FAQ
Will turning on Safe Attachments stop all email-borne malware?
No. Safe Attachments stops many attachment-based threats by sandboxing, but it doesn’t block malicious links in email bodies or inspect files encrypted by users; pair it with URL protection, DKIM/SPF/DMARC and user training.
How long does it take to enable and see policy changes apply?
Configuring a policy typically takes around 1–2 hours; Microsoft policy changes can take up to 24 hours to propagate across all mailboxes in a tenant.
Is Safe Attachments included in Microsoft 365 Business Standard?
Safe Attachments is part of Microsoft Defender for Office 365, which is an add-on to many business plans; check your licensing or speak to your Microsoft reseller before assuming it’s included.







